GHSA-2x8c-95vh-gfv4 · Severity: high — A signal handler race condition was found in OpenSSH's server (sshd), where a client does not...
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
Conclusion & alert: CVE-2024-6387 is rated High Exploit Risk (82.6/100): CVSS High severity, with high exploitation likelihood (EPSS 63.83%, 98th percentile). Core evidence: 10 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 52269 | exploit_db | edb | 2025-04-22 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-01 | 63.05% | 63.83% | +0.79% |
| 2 | 2026-05-30 | 63.83% | 63.05% | -0.79% |
| 3 | 2026-05-29 | — | 63.83% | — |
Full EPSS history (139 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.1 | HIGH |
|
2.2 | 5.9 | [email protected] |
| 8.1 | 3.1 | HIGH |
|
2.2 | 5.9 | [email protected] |
GHSA-2x8c-95vh-gfv4 · Severity: high — A signal handler race condition was found in OpenSSH's server (sshd), where a client does not...
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-6387: 1 source package rows (openssh); 10 state rows across 7 repos (3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 7, open 3. | https://security.alpinelinux.org/vuln/CVE-2024-6387 |
debian
|
unimportant | CVE-2024-6387 unimportant priority: Debian including 1 source packages (openssh), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2024-6387 |
gentoo
|
high | CVE-2024-6387: 1 GLSA(s) (202407-09), 1 atom(s) (net-misc/openssh); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2024-6387 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2024-6387 |
suse
|
high | CVE-2024-6387 severity important: SUSE including 312 source package names (15.7.20.5.1:openssh-9.6p1-150600.6.3.1, 15.7.20.5.1:openssh-clients-9.6p1-150600.6.3.1, …), 1140 product×package rows across 197 product lines (Container suse/git, Container suse/hpc/warewulf4-x86_64/sle-hpc-node, … (197 product lines)): Fixed 625, Known Not Affected 284, Known Affected 231. | https://www.suse.com/security/cve/CVE-2024-6387/ |
ubuntu
|
high | CVE-2024-6387 high priority: Ubuntu including 2 source packages (openssh, openssh-ssh1), 14 status rows across 8 suites (bionic, focal, jammy, mantic, noble, trusty, upstream, xenial): not-affected 9, released 4, ignored 1. | https://ubuntu.com/security/CVE-2024-6387 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| sonicwall | sma_6200_firmware | — | cpe:2.3:o:sonicwall:sma_6200_firmware:-:*:*:*:*:*:*:* |
| sonicwall | sma_7200_firmware | — | cpe:2.3:o:sonicwall:sma_7200_firmware:-:*:*:*:*:*:*:* |
| arista | eos | >= 4.32.0, <= 4.32.1f | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 23.10 | cpe:2.3:o:canonical:ubuntu_linux:23.10:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 24.04 | cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:* |
| almalinux | almalinux | 9.0 | cpe:2.3:o:almalinux:almalinux:9.0:-:*:*:*:*:*:* |
| sonicwall | sma_6210_firmware | — | cpe:2.3:o:sonicwall:sma_6210_firmware:-:*:*:*:*:*:*:* |
| sonicwall | sma_7210_firmware | — | cpe:2.3:o:sonicwall:sma_7210_firmware:-:*:*:*:*:*:*:* |
| sonicwall | sma_8200v_firmware | — | cpe:2.3:o:sonicwall:sma_8200v_firmware:-:*:*:*:*:*:*:* |
| sonicwall | sra_ex_7000_firmware | — | cpe:2.3:o:sonicwall:sra_ex_7000_firmware:-:*:*:*:*:*:*:* |
| netapp | a1k_firmware | — | cpe:2.3:o:netapp:a1k_firmware:-:*:*:*:*:*:*:* |
| netapp | a70_firmware | — | cpe:2.3:o:netapp:a70_firmware:-:*:*:*:*:*:*:* |
| netapp | a90_firmware | — | cpe:2.3:o:netapp:a90_firmware:-:*:*:*:*:*:*:* |
| netapp | a700s_firmware | — | cpe:2.3:o:netapp:a700s_firmware:-:*:*:*:*:*:*:* |
| netapp | 8300_firmware | — | cpe:2.3:o:netapp:8300_firmware:-:*:*:*:*:*:*:* |
| netapp | 8700_firmware | — | cpe:2.3:o:netapp:8700_firmware:-:*:*:*:*:*:*:* |
| netapp | a400_firmware | — | cpe:2.3:o:netapp:a400_firmware:-:*:*:*:*:*:*:* |
| netapp | c400_firmware | — | cpe:2.3:o:netapp:c400_firmware:-:*:*:*:*:*:*:* |
| netapp | a250_firmware | — | cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:* |
| netapp | 500f_firmware | — | cpe:2.3:o:netapp:500f_firmware:-:*:*:*:*:*:*:* |
| netapp | c250_firmware | — | cpe:2.3:o:netapp:c250_firmware:-:*:*:*:*:*:*:* |
| netapp | a800_firmware | — | cpe:2.3:o:netapp:a800_firmware:-:*:*:*:*:*:*:* |
| netapp | c800_firmware | — | cpe:2.3:o:netapp:c800_firmware:-:*:*:*:*:*:*:* |
| netapp | a900_firmware | — | cpe:2.3:o:netapp:a900_firmware:-:*:*:*:*:*:*:* |
| netapp | a9500_firmware | — | cpe:2.3:o:netapp:a9500_firmware:-:*:*:*:*:*:*:* |
| netapp | c190_firmware | — | cpe:2.3:o:netapp:c190_firmware:-:*:*:*:*:*:*:* |
| netapp | a150_firmware | — | cpe:2.3:o:netapp:a150_firmware:-:*:*:*:*:*:*:* |
| netapp | a220_firmware | — | cpe:2.3:o:netapp:a220_firmware:-:*:*:*:*:*:*:* |
| netapp | fas2720_firmware | — | cpe:2.3:o:netapp:fas2720_firmware:-:*:*:*:*:*:*:* |
| netapp | fas2750_firmware | — | cpe:2.3:o:netapp:fas2750_firmware:-:*:*:*:*:*:*:* |
| netapp | fas2820_firmware | — | cpe:2.3:o:netapp:fas2820_firmware:-:*:*:*:*:*:*:* |
| netapp | bootstrap_os | — | cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:* |
| apple | macos | >= 12.0, < 12.7.6 | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
| apple | macos | >= 13.0, < 13.6.8 | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
| apple | macos | >= 14.0, < 14.6 | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
| openbsd | openssh | < 4.4 | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* |
| openbsd | openssh | >= 8.6, <= 9.8 | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* |
| openbsd | openssh | 4.4 | cpe:2.3:a:openbsd:openssh:4.4:-:*:*:*:*:*:* |
| openbsd | openssh | 8.5 | cpe:2.3:a:openbsd:openssh:8.5:p1:*:*:*:*:*:* |
| openbsd | openssh | 8.6 | cpe:2.3:a:openbsd:openssh:8.6:-:*:*:*:*:*:* |
| redhat | openshift_container_platform | 4.0 | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 9.0 | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_eus | 9.4 | cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64 | 9.0_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_arm_64_eus | 9.4_aarch64 | cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.4_aarch64:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 9.0_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 9.4_s390x | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.4_s390x:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian | 9.0_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:9.0_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian_eus | 9.4_ppc64le | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.4_ppc64le:*:*:*:*:*:*:* |
| redhat | enterprise_linux_server_aus | 9.4 | cpe:2.3:o:redhat:enterprise_linux_server_aus:9.4:*:*:*:*:*:*:* |
| suse | linux_enterprise_micro | 6.0 | cpe:2.3:o:suse:linux_enterprise_micro:6.0:*:*:*:*:*:*:* |
| debian | debian_linux | 12.0 | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 22.04 | cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 22.10 | cpe:2.3:o:canonical:ubuntu_linux:22.10:*:*:*:-:*:*:* |
| canonical | ubuntu_linux | 23.04 | cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:lts:*:*:* |
| amazon | amazon_linux | 2023.0 | cpe:2.3:o:amazon:amazon_linux:2023.0:*:*:*:*:*:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
| netapp | e-series_santricity_os_controller | >= 11.0.0, <= 11.70.2 | cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:* |
| netapp | ontap | 9 | cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:* |
| netapp | ontap_select_deploy_administration_utility | — | cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* |
| netapp | ontap_tools | 9 | cpe:2.3:a:netapp:ontap_tools:9:*:*:*:*:vmware_vsphere:*:* |
| netapp | ontap_tools | 10 | cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:-:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p1:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p10:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p11:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p2:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p3:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p4:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p5:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p6:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p7:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p8:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p9:*:*:*:*:*:* |
| freebsd | freebsd | 13.3 | cpe:2.3:o:freebsd:freebsd:13.3:-:*:*:*:*:*:* |
| freebsd | freebsd | 13.3 | cpe:2.3:o:freebsd:freebsd:13.3:p1:*:*:*:*:*:* |
| freebsd | freebsd | 13.3 | cpe:2.3:o:freebsd:freebsd:13.3:p2:*:*:*:*:*:* |
| freebsd | freebsd | 13.3 | cpe:2.3:o:freebsd:freebsd:13.3:p3:*:*:*:*:*:* |
| freebsd | freebsd | 14.0 | cpe:2.3:o:freebsd:freebsd:14.0:-:*:*:*:*:*:* |
| freebsd | freebsd | 14.0 | cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:* |